Description
A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Published: 2026-09-08
Score: 1.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: Configuration Tampering
Action: Patch Now
AI Analysis

Impact

The vulnerability is a classic CSRF flaw that allows an attacker to manipulate router settings through a victim administrator, potentially disrupting device functionality. The flaw carries no confidentiality impact as data interception is not enabled, but it can undermine integrity of router configuration and availability of the device by altering key network parameters. The weakness corresponds to CWE-352, showing a failure in ensuring request authenticity.

Affected Systems

Affected models include the NETGEAR XR1000, XR1000v2, and XR500 gaming routers. The patch version for XR1000 and XR1000v2 is V1.1.0.22. The XR500 is marked end‑of‑support, so no security updates are expected beyond its current release.

Risk and Exploitability

The CVSS score of 1.8 indicates a low severity. With an EPSS score of 0.00119, equivalent to less than 1%, the likelihood of exploitation is very low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is social engineering, where an attacker tricks an administrator into submitting a malicious request, as no remote network‑level exploitation path is described.

Generated by OpenCVE AI on September 10, 2026 at 03:42 UTC.

Remediation

Vendor Solution

Devices with automatic updates enabled may already have this patch applied. If not, please check the firmware version and update it to the latest. Fixed in: ProductFixed VersionXR1000 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000 XR1000v2 Nighthawk WiFi 6 Pro Gaming Router V1.1.0.22 https://www.netgear.com/support/product/xr1000v2 XR500 (EoS) Nighthawk Pro Gaming Router v2.3.5.152 https://www.netgear.com/support/product/xr500 Models marked (EoS) have reached End-of-Support phase, and no security updates are planned. NETGEAR strongly recommends that you retire these devices and upgrade to a newer NETGEAR device for continued security support.


OpenCVE Recommended Actions

  • Upgrade the device firmware to the latest version (V1.1.0.22 for XR1000 and XR1000v2, or the newest available for XR500).
  • Ensure that the device’s automatic update feature is enabled or schedule regular firmware updates to keep the router patched.
  • If you are using an XR500 model, retire the device and replace it with a newer NETGEAR device that continues to receive security support, since it is End‑of‑Support and will not receive further updates.

Generated by OpenCVE AI on September 10, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Netgear xr1000 Firmware
Netgear xr1000v2 Firmware
Netgear xr500 Firmware
CPEs cpe:2.3:h:netgear:xr1000:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr1000v2:-:*:*:*:*:*:*:*
cpe:2.3:h:netgear:xr500:-:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr1000v2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:netgear:xr500_firmware:*:*:*:*:*:*:*:*
Vendors & Products Netgear xr1000 Firmware
Netgear xr1000v2 Firmware
Netgear xr500 Firmware

Thu, 10 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Netgear
Netgear xr1000
Netgear xr1000v2
Netgear xr500
Vendors & Products Netgear
Netgear xr1000
Netgear xr1000v2
Netgear xr500

Wed, 09 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/V:D/RE:L/U:Amber'}

cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H'}


Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations with active assistance from the router administrator. There is no confidentiality impact due to this vulnerability.
Title A CSRF vulnerability exists in certain NETGEAR XR series devices
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Netgear Xr1000 Xr1000 Firmware Xr1000v2 Xr1000v2 Firmware Xr500 Xr500 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NETGEAR

Published:

Updated: 2026-09-09T03:51:25.403Z

Reserved: 2026-05-21T17:29:08.100Z

Link: CVE-2026-9215

cve-icon Vulnrichment

Updated: 2026-09-08T18:26:17.037Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:17.893

Modified: 2026-09-11T21:20:24.780

Link: CVE-2026-9215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T06:45:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)